GDPR & Trust

This page is maintained by Launch Safe. It explains, in plain language, how we build and operate the platform in line with the UK GDPR and the Data Protection Act 2018. It is not a certification or a substitute for our full Privacy Policy.

Our approach

GDPR compliance is not a badge we buy — it is an ongoing way we design and operate the platform. Because Launch Safe handles names, contact details, resident communications, inspection records and contractor information, data protection is built into the product from the outset.

Data protection principles in practice

Lawful, fair, transparent

Clear notices about what we collect and why. No hidden processing, no third-party marketing, no data sales.

Data minimisation

We collect only what the platform needs to manage compliance — no unnecessary personal fields, no shadow profiles.

Access & rectification

Users can view and correct their profile data at any time. Organisation admins control access to building records.

Right to erasure

Account and personal data deletion is available on request from the Profile page or by emailing us.

Storage limitation

Personal data is retained only while your organisation has an active subscription plus a defined post-termination window for legal and audit obligations.

Integrity & confidentiality

Encryption in transit, role-based access, row-level security in the database, and least-privilege service credentials.

Controller and processor roles

Launch Safe acts as data controller for account information (the details used to create and manage a Launch Safe account) and as data processor for the compliance data uploaded by our customer organisations (buildings, inspections, actions, documents and related records). Customer organisations remain the controller of the compliance data they upload.

What we collect

  • Account data — name, work email, organisation, role.
  • Compliance data — building records, inspection notes, photos, documents, actions.
  • Contact information — resident, contractor and stakeholder details entered by users.
  • Technical data — browser, device, IP address and audit logs needed to operate the service securely.

Your rights

Depending on your location and role, you may exercise the following rights over your personal data:

  • Access — request a copy of the personal data we hold about you.
  • Rectification — correct inaccurate or incomplete data.
  • Erasure — request deletion of your account and personal data.
  • Restriction and objection — limit or object to certain processing.
  • Portability — receive your data in a common, machine-readable format.

Signed-in users can export or request deletion of their profile data from the Profile page. All other requests can be sent to info@launchsafe.co.uk and are actioned within one calendar month.

Sub-processors

We use a small number of vetted providers to host the platform, store data, deliver email and run AI-assisted features. Each is bound by a data processing agreement requiring appropriate security and confidentiality. A current sub-processor list is available on request.

International transfers

Where personal data is transferred outside the UK or EEA, we rely on appropriate safeguards such as UK International Data Transfer Agreements or Standard Contractual Clauses with our sub-processors.

Breach response

We maintain an internal process to detect, contain and investigate personal data incidents. Where a reportable breach occurs, we will notify the ICO within 72 hours and inform affected customers without undue delay in line with UK GDPR Articles 33 and 34.

Contact

For any data protection questions, DPA requests or subject access requests, email info@launchsafe.co.uk. You also have the right to complain to the UK Information Commissioner's Office (ICO) at ico.org.uk.